1. Authentication & Access Control
We implement multiple layers of authentication security:
- Password hashing: All passwords are hashed using bcrypt with a cost factor of 12. We never store or log plaintext passwords.
- Google OAuth: Users may alternatively authenticate via Google OAuth 2.0, eliminating the need to manage a separate password.
- Session management: Sessions are managed via signed JWT tokens with a 7-day absolute expiry and 24-hour sliding renewal window. Tokens are stored as secure, HttpOnly cookies.
- Role-based access: Each user can only access their own deals and documents. All API routes verify the authenticated user’s identity before returning data.
2. Encryption
2.1 In Transit
All connections to the Service are encrypted via HTTPS (TLS 1.2+). We enforce HTTP Strict Transport Security (HSTS) with includeSubDomains and preload directives, ensuring browsers always connect over a secure channel.
2.2 At Rest
Our database provider (Neon) encrypts all data at rest using AES-256 encryption. Backups are also encrypted. We do not store credit card numbers or full payment credentials — all payment processing is handled by Stripe, which maintains PCI DSS Level 1 compliance.
3. Infrastructure & Hosting
| Component | Provider | Security Notes |
|---|---|---|
| Application hosting | Vercel | SOC 2 Type II certified; automatic HTTPS; isolated serverless functions |
| Database | Neon (serverless PostgreSQL) | SOC 2 Type II certified; encrypted at rest (AES-256) and in transit (TLS) |
| Payments | Stripe | PCI DSS Level 1; EM never handles raw card data |
| AI processing | Anthropic (Claude API) | SOC 2 Type II; commercial API data is not used for model training |
| Authentication | NextAuth 4.24 + Google OAuth | Industry-standard OAuth 2.0 / OpenID Connect flows |
We do not operate our own physical servers. All infrastructure runs on managed cloud platforms with their own security certifications and compliance programs.
4. API Security
Our API routes are protected by multiple security controls:
- Authentication required: All data-access API routes require a valid session token. Unauthenticated requests receive a 401 response.
- Rate limiting: Per-IP sliding-window rate limiting is enforced on all API routes to prevent brute-force attacks and abuse.
- Input validation: All user inputs are validated and sanitized server-side before processing or storage.
- CORS policy: Cross-origin requests are restricted to the Service’s own domain.
- Security headers: We set standard security headers including Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy.
5. Data Handling & AI Processing
When you use AI features (document extraction, financial analysis, chat), your document content and deal data are sent to Anthropic’s Claude API for processing. Important safeguards:
- Under Anthropic’s commercial API terms, your data is not used to train AI models
- Data is transmitted to Anthropic over encrypted connections (TLS)
- We send only the minimum data required for each specific AI operation
- AI processing results are stored in our database, associated with your account, and subject to the same retention policies as all other user data
6. Data Retention & Deletion
- Trial accounts: Automatically deleted 14 days after trial expiration if not converted to a paid plan.
- Paid accounts: Data retained during active subscription. After cancellation, retained for 30 days (reactivation window), then permanently deleted.
- Server logs: Retained for up to 90 days for security and debugging purposes, then automatically purged.
- Data deletion requests: You may request deletion of your data at any time by emailing [email protected]. We process deletion requests within 30 days.
7. Compliance
We design our platform and policies to comply with applicable data protection regulations:
- GDPR & UK-GDPR: Data processing agreements with all processors, Standard Contractual Clauses for international transfers, data subject rights (access, rectification, erasure, portability).
- CCPA / CPRA: We do not sell or share personal information. California residents may exercise their rights as described in our Privacy Policy.
- PCI DSS: EM Underwriting does not handle raw credit card data. All payment processing is delegated to Stripe (PCI DSS Level 1 certified). Our PCI boundary is Stripe — not EM.
Note: EM Underwriting does not currently hold SOC 2, ISO 27001, HIPAA, or FedRAMP certifications. We are transparent about this. Our security posture relies on vetted, certified infrastructure providers (Vercel, Neon, Stripe, Anthropic) and the application-level controls described on this page.
8. Vulnerability Reporting
We take security vulnerabilities seriously. If you discover a potential security issue, please report it responsibly:
Security Contact: [email protected]
Please include a description of the issue, steps to reproduce, and any relevant screenshots or logs. We aim to acknowledge reports within 48 hours and will work with you to understand and address the issue promptly.
We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and address it.
9. Incident Response
In the event of a confirmed security incident involving unauthorized access to user data, we will:
- Investigate and contain the incident as quickly as possible
- Notify affected users by email within 72 hours of confirmation, as required by GDPR and applicable law
- Notify relevant supervisory authorities where legally required
- Provide a clear description of what data was affected and what steps we are taking
- Implement measures to prevent recurrence
10. Contact
For security questions, concerns, or vulnerability reports:
EM Underwriting
Email: [email protected]
For details on how we collect and process your data, see our Privacy Policy. For the terms governing your use of the Service, see our Terms of Service.